Several people, one machine.
WHAT TO AVOID
A shared account and a shared password.
WHY
Nothing can be attributed, and removing one person means changing it for everyone.
WHAT TO DO INSTEAD
An account per person, with their own key.
WHAT TO GRANT
sudo, restricted where practical.
WHAT TO LOG
Every elevated command.
WHAT TO DOCUMENT
Who has access, to what, and why.
WHAT TO REVIEW
That list, periodically and after every departure.
WHAT TO DO WHEN SOMEONE LEAVES
Remove their account Remove their keys from every authorised file Rotate any shared credential they knew
WHY THAT LAST POINT
Shared secrets they held remain valid otherwise.
HOW TO FIND KEYS ACROSS ACCOUNTS
Search every home directory's authorised keys file.
WHY THAT SEARCH MATTERS
Keys accumulate, and nobody removes them.
WHAT TO CHECK FOR
Keys nobody can identify.
WHAT TO DO ABOUT THEM
Remove them, after confirming they are unused.
WHAT TO CONSIDER FOR CONTRACTORS
Time-limited access, and separate accounts.
WHAT TO NEVER DO
Give root to anyone who does not need it Leave access in place because removing it is awkward